filebeat:
 prospectors:
  - type: log
    paths:
      - "/var/ossec/logs/alerts/alerts.json"
    document_type: json
    json.message_key: log
    json.keys_under_root: true
    json.overwrite_keys: true

output.{{ beats_output_type }}:
  hosts: ['{{ beats_output_host | list | join(":" + beats_output_port + "', '") }}:{{ beats_output_port }}']
  loadbalance: true
  protocol: "http"
{% if beats_output_auth %}
  username: "{{ beats_output_user }}"
  password: "{{ beats_output_pass }}"
{% endif %}

  #pipeline: geoip
  indices:
    - index: 'wazuh-alerts-3.x-%{+yyyy.MM.dd}'

logging.level: warning
logging.to_syslog: true
http:
  enabled: true
  host: localhost
  port: {{ beats_port_arg.http }}